PT-2019-15715 · Allied Telesis · At-Gs950/8

Dr. H. Benda

+1

·

Publicado

2019-11-29

·

Atualizado

2020-02-06

·

CVE-2019-18922

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Allied Telesis AT-GS950/8 versions prior to Firmware AT-S107 V.1.1.3 [1.00.047]
Description A Directory Traversal issue in the Web interface allows unauthenticated attackers to read arbitrary system files via a GET request. This issue affects an End-of-Life product.
Recommendations For Allied Telesis AT-GS950/8 versions prior to Firmware AT-S107 V.1.1.3 [1.00.047], update to Firmware AT-S107 V.1.1.3 [1.00.047] or later to resolve the issue. As a temporary workaround, consider restricting access to the Web interface until a patch is applied.

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-18922

Produtos afetados

At-Gs950/8